Cork had been audited in whole or in part by four different security firms. The project's funders include Andreessen Horowitz, OrangeDAO, and Steakhouse Financial, and Cork is a part of Andreessen Horowitz's Crypto Startup Accelerator.
Cork Protocol exploited for $12 million
Cetus DEX exploited for $223 million; some funds "paused"
This led some to question how decentralized the project truly is if the funds can be frozen in such a way.
Curve Finance website and Twitter account hacked
Then, on May 12, the project posted a warning that the website for the Curve frontend was "hijacked" in an apparent domain takeover.
This is not the first such compromise for Curve, which suffered a frontend compromise in August 2022 that resulted in $620,000 in losses (later recovered with the help of some exchanges).
$330 million in Bitcoin apparently stolen; laundering spikes Monero price by over 40%
Term Finance loses $1.65 million due to misconfiguration, recovers $1 million
Loopscale hacked for $5.8 million two weeks after launch
$5 million in tokens stolen from ZKsync
ZK Sync offered a 10% "bug bounty" to the thief, who accepted and returned 90% of the stolen funds.
KiloEx exploited for $7.5 million
KiloEx halted trading on the platform while investigating the exploit, and contacted the hacker to try to negotiate a 90% return of funds.
KiloEx later announced that the recovery had been successful, and that they would pay out the 10% "bounty".
zkLend thief gets robbed
On March 31, the attacker sent an on-chain message to the platform, writing: "Hello I tried to move funds to tornado but I used a phishing website and all the funds have been lost. I am devastated. I am terribly sorry for all the havoc and losses caused. All the 2930 eth have been taken by that site owners. I do not have coins. Please redirect your efforts towards those site owners to see if you can recover some of the money. I am sorry."
The zkLend project instructed the thief to return any remaining funds to their wallets, though no such transfer has happened yet.
There has been substantial conversation over whether the hacker had truly been in turn scammed out of the stolen funds, had made up a fake phishing site to try to obscure the path of stolen money, or perhaps whether the whole event had been an April Fools' joke. However, zkLend noted on Twitter that the phishing website, which imitates the Tornado Cash platform, has been operational for five years and is likely not connected to the hacker.
- On-chain messages between zkLend and thief
- Tweet by zkLend [archive]
Coinbase customer loses $35 million in bitcoin theft
zachxbt has previously accused Coinbase of not doing enough to protect customers from hundreds of millions of dollars in scams, and he noted that in these cases, Coinbase had not marked the thief wallets as malicious in various cryptocurrency compliance tools.
- Telegram post by zachxbt [archive]